The package includes a README, tests, and a stable release, while the repository is not archived or deprecated. Its proprietary licensing, no commits for three months, and repository/package naming mismatch make long-term support and provenance uncertain.
43%
Total Score
0
50
75
50
The repository had no commits and no active maintainers during the last three months. Combined with the long release gap, this materially raises abandonment risk.
The package declares 43 runtime dependencies, including a substantial Symfony and application stack. This increases update and compatibility maintenance burden.
The manifest declares a proprietary license, with no license file detected in the package or repository. This limits transparency and may restrict dependable reuse.
The package runs post-install and post-update scripts, adding execution during dependency operations. The signal does not show that these scripts are unsafe, so this is a moderate review concern rather than a verdict.
The package has four releases but none in the last 12 months; its latest release was about 15 months ago. This indicates a real maintenance and abandonment concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version * | — | — |
ramsey/uuid Version ^4.7 | — | — |
symfony/uid Version 6.* | — | — |
doctrine/orm Version * | — | — |
symfony/flex Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.